AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-2148

LOW · CVSS 3.6 EPSS 0.39%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-05-12 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 3.6. It affects Linux. It may lead to a denial-of-service condition.

CVE
CVE-2008-2148
Severity
LOW
CVSS
3.6
EPSS
0.39%
Linux

Original NVD Description

The utimensat system call (sys_utimensat) in Linux kernel 2.6.22 and other versions before 2.6.25.3 does not check file permissions when certain UTIME_NOW and UTIME_OMIT combinations are used, which allows local users to modify file times of arbitrary files, possibly leading to a denial of service.